Comment by PaulCarrack
9 hours ago
Based on the amount of modem CVEs posted in the monthly Android security bulletins, I think it's safe to assume that if you are no longer getting updates then there are unpatched vulnerabilities in them.
9 hours ago
Based on the amount of modem CVEs posted in the monthly Android security bulletins, I think it's safe to assume that if you are no longer getting updates then there are unpatched vulnerabilities in them.
Based on the artificial delays Google introduces into the Android patching process, on the general crappiness of mobile firmware and the sleaziness of major mobile chipset vendors, I think it's safe to assume that even if you are supposedly getting updates, there are unpatched zero-day vulnerabilities in them. Usually under ongoing attack, at least by professional phone cracking software vendors and secret services.
>Based on the artificial delays Google introduces into the Android patching process, on the general crappiness of mobile firmware and the sleaziness of major mobile chipset vendors, I think it's safe to assume that even if you are supposedly getting updates, there are unpatched zero-day vulnerabilities in them.
Maybe if you include third party android OEMs like samsung, but google pixels are as up to date as you can get.
Pixels running GrapheneOS sure, but stock Pixels lag months behind patches that exist but not yet shipped. Check any bulletin and it links to git commits to months ago.
2 replies →
Android Security Bulletins don't list the vast majority of firmware, driver, HAL and especially Linux kernel vulnerabilities. Those list a large subset of the High and Critical severity Android Open Source Project (AOSP) vulnerabilities backported to older releases along with a tiny portion of non-AOSP vulnerabilities. AOSP vulnerabilities below High and Critical severity aren't backported so those aren't listed. Non-AOSP vulnerabilities for Pixels are covered in the Pixel Update Bulletins with many of those being vulnerabilities in components used by other devices. Each OEM is supposed to make their own equivalent to the Pixel Update Bulletins, but they aren't required to provide those updates to claim the latest patch level.